Paper 2025/1885
Correction Fault Attack on CROSS under Unknown Bit Flips
Abstract
Recognising the need for PQC signature schemes with different size and performance trade-offs than the ML-DSA and SLH-DSA standards, in 2023 NIST launched a competition for additional signature algorithms. Among the current candidates in this competition is CROSS, a code-based scheme derived from the syndrome-decoding problem and suitable for memory-constrained devices. This paper presents a fault attack on CROSS that recovers the secret key by flipping one or more bits in the scheme’s public parity-check matrix. Unlike previous PQC fault attacks that typically rely on precisely controlled fault injections, which is often an unrealistic assumption, our approach exploits bit flips with unknown position and value, resembling the Rowhammer fault model. The attack builds upon the correction-based methodology introduced for Dilithium (Euro S&P’22; CHES’24) and exploits structural properties of CROSS to substantially relax attacker requirements. We demonstrate the attack on an ARM Cortex-M4 processor using voltage fault injection. We further show that prior work on partial key exposure attacks (CRYPTO'22) can be extended to CROSS under non-trivial erasure rates, reducing the attack complexity. The attack remains effective in the presence of memory-integrity protection mechanisms such as error-correcting codes. Finally, we propose countermeasures for hardening CROSS implementations against physical attacks.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- A minor revision of an IACR publication in TCHES 2026
- DOI
- 10.46586/tches.v2026.i2.192-217
- Keywords
- Fault InjectionCROSSCode-based CryptographyPost-Quantum Digital SignaturePartial Key Exposure Attack
- Contact author(s)
-
jendral @ kth se
dubrova @ kth se
qian guo @ eit lth se
thomas johansson @ eit lth se - History
- 2026-04-29: revised
- 2025-10-09: received
- See all versions
- Short URL
- https://ia.cr/2025/1885
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1885,
author = {Sönke Jendral and Elena Dubrova and Qian Guo and Thomas Johansson},
title = {Correction Fault Attack on {CROSS} under Unknown Bit Flips},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1885},
year = {2025},
doi = {10.46586/tches.v2026.i2.192-217},
url = {https://eprint.iacr.org/2025/1885}
}